I removed the hacker's email from my Microsoft account, but verification codes are still being sent to that email

john israel penalosa 0 Reputation points
2026-08-06T15:09:53.19+00:00

Hello,

I need some advice regarding the security of my Microsoft account.

My Microsoft account was recently hacked. The attacker changed my password and replaced my recovery email with their own email address. Because of that, when I initially tried to reset my password, the verification code was being sent to the hacker's email instead of mine.

Fortunately, I remembered that I had another laptop where I was still signed in using Windows Hello/passkey. I was able to access my account from that device.

After logging in, I immediately:

  • Changed my password.
  • Removed the hacker's recovery email from my account.
  • Removed the hacker's devices from my account.
  • Reviewed my account settings for anything suspicious.

However, I noticed something that concerns me.

When I go to certain security settings, Microsoft still asks for a verification code, and the code is being sent to the hacker's email address—even though I already removed that email from my account.

My questions are:

  1. Is this normal? Could this be because of Microsoft's 30-day security information change waiting period?
  2. Does this mean the hacker can still receive verification codes?
  3. Can the hacker still reset my password or regain access to my account because verification codes are still being sent to their email?
  4. Is there anything else I should do to fully secure my account?

I'm worried that even though I removed the hacker's email, they might still be able to recover my account.

Any advice or explanation would be greatly appreciated.

Thank you.

Windows for home | Windows 11 | Security and privacy
0 comments No comments

2 answers

Sort by: Most helpful
  1. Nathan R 500 Reputation points Independent Advisor
    2026-08-06T16:26:58.4266667+00:00

    Hey there, john israel penalosa

    Is this normal?

    From what you have described in your question, no this isn't normal.

    Once you have updated your security information, this should stop the attacker from gaining access onto your account. However, in your case the attacker is still signing into your account.

    Could this be because of Microsoft's 30-day security information change waiting period?

    The waiting period will prevent you from updating or changing your security information on your account, while providing the opportunity for the account owner to contest the changes via an email they send you. During this period, the system will prevent both of you from signing into the Microsoft account security page here: https://account.live.com/proofs/manage/additional

    If you are able to sign-in on that page, then this hasn't been locked. You would be greeted by a screen telling you you have to wait 30 days. More information about this can be found here: https://support.microsoft.com/en-us/accounts-billing/manage/what-does-security-info-change-is-still-pending-mean

    Does this mean the hacker can still receive verification codes?

    No, not as far as I am aware.

    However, with this being said, I do think the attacker is able to sign into your account using one last method most people don't realise that exists on the Microsoft account.

    A personal Microsoft account has one last method people can use for when they loose access to their security information either because it has been changed by an attacker, or they suddenly loose access to it. Each Microsoft account can have a recovery code that can be generated as a way to gain access onto the account, for if all else fails. Only one recovery code can be active at one time, so when a new recovery code is generated, the previous one will no longer work.

    As I said, most people don't realise this exists. Please can you sign into your account on your security page here: https://account.live.com/proofs/manage/additional

    Once you have signed into your account, please scroll all of the way down to the bottom of the page until you come to a section called "Recovery code"

    User's image

    Please can you click onto "Generate a new code" which is a blue hyperlink

    User's image

    This will generate you a new code you can use for your Microsoft account. If the attacker is using this method to gain access to your account again, the previous code they generated will no longer work.

    Please make sure you keep that code safe. I have mine printed and kept in a secure, safe place for if I need it.

    Can the hacker still reset my password or regain access to my account because verification codes are still being sent to their email?

    As I mentioned above. I think the attacker has probably created a recovery code and is using this to gain access onto your Microsoft account.

    Is there anything else I should do to fully secure my account?

    Please follow the steps above to create a recovery code. Once you have done this, please:

    • Make sure all of the security information is up-to date,
    • make sure you remove any security information that may be compromised or that is not yours (You said you have already done this),
    • Make sure you click onto the option to force sign out of all of your devices,
    • Make sure two-step verification is enabled,
    • Please sign into your names page here: https://account.live.com/names/manage and make sure they haven't added any of their information to it,

    The other thing you can do, is sign into your recent activity page here: https://account.live.com/Activity

    Please check the recent activity page to see if they have managed to sign into your account and what they have managed to use to sign into your account.

    Hope this information helps,
    Nathan

    Was this answer helpful?

    0 comments No comments

  2. AI answer

    2026-08-06T15:10:24.4533333+00:00

    Yes, this can be consistent with the 30-day security info change process.

    If all previous security info was removed and replaced, the account can enter a restricted 30-day state. During that period, Microsoft shows "Your security info change is still pending" or "You can't access this site right now". The documented behavior is that the old security info was removed and replaced with new info, and the changes take 30 days to fully take effect.

    What this means in this situation:

    1. The behavior can be normal during the pending period If the attacker-added security info was part of a security info change flow, some verification prompts can still reflect that pending state until the 30 days complete or the request is canceled.
    2. The old or replaced security info may still be involved during the pending window Microsoft states that notifications are sent during the 30 days to the original security info to alert that changes were made. That is why seeing the attacker-controlled address still appear can indicate the account is in that pending security-change state.
    3. The 30-day process cannot be expedited Microsoft states it cannot be expedited unless the request is canceled.

    What to do next:

    1. Go to the Microsoft account Security page.
    2. Check whether the account shows "Your security info change is still pending".
    3. If that message appears:
      • If the security removal/change was done personally, select cancel this request and follow the prompts.
      • If the change was not authorized, select let us know in that same window and follow the prompts.

    Additional steps to secure the account:

    1. On the Security basics page, select Review activity and inspect recent sign-in attempts.
    2. For any activity that was not recognized, use This wasn't me or Secure your account.
    3. Change the password again from Security basics if there is any doubt that the attacker still knows it.
    4. On Advanced security options, add another way to sign in or verify, and make sure the listed phone numbers and email addresses are current.
    5. Consider going passwordless. Microsoft lists Windows Hello, Microsoft Authenticator, SMS or email codes, and physical security keys as passwordless methods.
    6. If all security info was removed from the account at any point, avoid removing all methods again, because that puts the account into a restricted 30-day state.

    About whether the attacker can still regain access: the context confirms the 30-day pending state exists and that old/original security info is still part of the notification flow during that period, but it does not provide a definitive statement that the attacker can or cannot still reset the password solely because that address appears in verification prompts. The supported action is to check for the pending-change banner and use let us know if the change was unauthorized.


    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.